CVE-2016-1658

The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:novell:suse_package_hub_for_suse_linux_enterprise:12:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:46

Type Values Removed Values Added
References () http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html - () http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html -
References () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00040.html - () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00040.html -
References () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00041.html - () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00041.html -
References () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00049.html - () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00049.html -
References () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00050.html - () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00050.html -
References () http://rhn.redhat.com/errata/RHSA-2016-0638.html - () http://rhn.redhat.com/errata/RHSA-2016-0638.html -
References () http://www.debian.org/security/2016/dsa-3549 - () http://www.debian.org/security/2016/dsa-3549 -
References () https://codereview.chromium.org/1658913002 - () https://codereview.chromium.org/1658913002 -
References () https://crbug.com/573317 - () https://crbug.com/573317 -
References () https://security.gentoo.org/glsa/201605-02 - () https://security.gentoo.org/glsa/201605-02 -

07 Nov 2023, 02:30

Type Values Removed Values Added
References (CONFIRM) https://codereview.chromium.org/1658913002 - () https://codereview.chromium.org/1658913002 -
References (GENTOO) https://security.gentoo.org/glsa/201605-02 - () https://security.gentoo.org/glsa/201605-02 -
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2016-0638.html - () http://rhn.redhat.com/errata/RHSA-2016-0638.html -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00049.html - () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00049.html -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00050.html - () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00050.html -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00040.html - Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00040.html -
References (CONFIRM) https://crbug.com/573317 - () https://crbug.com/573317 -
References (CONFIRM) http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html - Vendor Advisory () http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_13.html -
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00041.html - Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00041.html -
References (DEBIAN) http://www.debian.org/security/2016/dsa-3549 - Third Party Advisory () http://www.debian.org/security/2016/dsa-3549 -

Information

Published : 2016-04-18 10:59

Updated : 2024-11-21 02:46


NVD link : CVE-2016-1658

Mitre link : CVE-2016-1658

CVE.ORG link : CVE-2016-1658


JSON object : View

Products Affected

debian

  • debian_linux

google

  • chrome

novell

  • suse_package_hub_for_suse_linux_enterprise

opensuse

  • leap
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control